Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
AttackFeed by Joe Wagner | Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack  - CyberScoop
Attack Feeds
Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack  – CyberScoop
March 24, 2026
AttackFeed by Joe Wagner | The Hidden Security Risks of Shadow AI in Enterprises  - The Hacker News
Attack Feeds
The Hidden Security Risks of Shadow AI in Enterprises  – The Hacker News
April 9, 2026
AttackFeed by Joe Wagner|Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack  – CyberScoop
Attack Feeds
Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack  – CyberScoop
March 3, 2026
AttackFeed by Joe Wagner | The CTEM Divide: Why 84% of Security Programs Are Falling Behind  - The Hacker News
Attack Feeds
The CTEM Divide: Why 84% of Security Programs Are Falling Behind  – The Hacker News
February 12, 2026
AttackFeed by Joe Wagner | Spanish police say they have arrested hacker who booked luxury hotel rooms for just one cent  - GRAHAM CLULEY
Attack Feeds
Spanish police say they have arrested hacker who booked luxury hotel rooms for just one cent  – GRAHAM CLULEY
February 20, 2026
AttackFeed by Joe Wagner | Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities  - The Hacker News
Attack Feeds
Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities  – The Hacker News
March 5, 2026

APPLE-SA-02-11-2026-2 iOS 18.7.5 and iPadOS 18.7.5  – Full Disclosure

Posted on February 16, 2026 By Joe-W
APPLE-SA-02-11-2026-2 iOS 18.7.5 and iPadOS 18.7.5  – Full Disclosure
Alert Feeds

  Posted by Apple Product Security via Fulldisclosure on Feb 16 APPLE-SA-02-11-2026-2 iOS 18.7.5 and iPadOS 18.7.5 iOS 18.7.5 and iPadOS 18.7.5 addresses the following issues. Information about the security content is also available at https://support.apple.com/126347. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Accessibility Available for: … Read More “APPLE-SA-02-11-2026-2 iOS 18.7.5 and iPadOS 18.7.5  – Full Disclosure” »

APPLE-SA-02-11-2026-3 macOS Tahoe 26.3  – Full Disclosure

Posted on February 16, 2026 By Joe-W
APPLE-SA-02-11-2026-3 macOS Tahoe 26.3  – Full Disclosure
Alert Feeds

  Posted by Apple Product Security via Fulldisclosure on Feb 16 APPLE-SA-02-11-2026-3 macOS Tahoe 26.3 macOS Tahoe 26.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/126348. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Admin Framework Available for: macOS Tahoe Impact: … Read More “APPLE-SA-02-11-2026-3 macOS Tahoe 26.3  – Full Disclosure” »

[Full Disclosure] CVE-2025-69690 & CVE-2025-69691 — Authenticated RCE in Netgate pfSense CE 2.7.2 and 2.8.0  – Full Disclosure

Posted on February 16, 2026 By Joe-W
[Full Disclosure] CVE-2025-69690 & CVE-2025-69691 — Authenticated RCE in Netgate pfSense CE 2.7.2 and 2.8.0  – Full Disclosure
Alert Feeds

  Posted by privexploits via Fulldisclosure on Feb 16 Advisory: Authenticated Remote Code Execution in pfSense CECVEs: CVE-2025-69690, CVE-2025-69691 Researcher: Nelson Adhepeau (privexploits () protonmail com) Date: February 2026 == RESPONSIBLE DISCLOSURE NOTICE == This advisory is published in accordance with responsible disclosure practices.  The vendor was notified on December 2, 2025, acknowledged the reports, … Read More “[Full Disclosure] CVE-2025-69690 & CVE-2025-69691 — Authenticated RCE in Netgate pfSense CE 2.7.2 and 2.8.0  – Full Disclosure” »

SEC Consult SA-20260212-0 :: Multiple Vulnerabilities in various Solax Power Pocket WiFi models  – Full Disclosure

Posted on February 16, 2026 By Joe-W
SEC Consult SA-20260212-0 :: Multiple Vulnerabilities in various Solax Power Pocket WiFi models  – Full Disclosure
Alert Feeds

  Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Feb 16 SEC Consult Vulnerability Lab Security Advisory < 20260212-0 > ======================================================================= title: Multiple Vulnerabilities             product: Various Solax Power Pocket WiFi models  vulnerable version: See section below       fixed version: See section below         … Read More “SEC Consult SA-20260212-0 :: Multiple Vulnerabilities in various Solax Power Pocket WiFi models  – Full Disclosure” »

Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers  – The Hacker News

Posted on February 16, 2026 By [email protected] (The Hacker News)
Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers  – The Hacker News
Attack Feeds

A new study has found that multiple cloud-based password managers, including Bitwarden, Dashlane, and LastPass, are susceptible to password recovery attacks under certain conditions. “The attacks range in severity from integrity violations to the complete compromise of all vaults in an organization,” researchers Matteo Scarlata, Giovanni Torrisi, Matilda Backendal, and Kenneth G. Paterson said.  – … Read More “Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers  – The Hacker News” »

Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens  – The Hacker News

Posted on February 16, 2026 By [email protected] (The Hacker News)
Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens  – The Hacker News
Attack Feeds

Cybersecurity researchers disclosed they have detected a case of an information stealer infection successfully exfiltrating a victim’s OpenClaw (formerly Clawdbot and Moltbot) configuration environment. “This finding marks a significant milestone in the evolution of infostealer behavior: the transition from stealing browser credentials to harvesting the ‘souls’ and identities of personal AI [  – Read More  … Read More “Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens  – The Hacker News” »

SMEs Wrong to Assume They Won’t Be Hit by Cyber-Attacks, NCSC Boss Warns –

Posted on February 16, 2026 By Joe-W
SMEs Wrong to Assume They Won’t Be Hit by Cyber-Attacks, NCSC Boss Warns –
Privacy/Governance Feed

NCSC’s Richard Horne has warned that cybercriminals do not care about business size and called for SMEs to act now to secure their organizations – Read More  –  

Vulnerabilities in Password Managers Allow Hackers to View and Change Passwords –

Posted on February 16, 2026 By Joe-W
Vulnerabilities in Password Managers Allow Hackers to View and Change Passwords –
Privacy/Governance Feed

Security researchers have challenged end-to-end encryption claims from popular commercial password managers – Read More  –  

Operation DoppelBrand Weaponizes Trusted Brands For Credential Theft –

Posted on February 16, 2026 By Joe-W
Operation DoppelBrand Weaponizes Trusted Brands For Credential Theft –
Privacy/Governance Feed

New phishing campaign dubbed Operation DoppelBrand targeted major financial firms like Wells Fargo – Read More  –  

OysterLoader Evolves With New C2 Infrastructure and Obfuscation –

Posted on February 16, 2026 By Joe-W
OysterLoader Evolves With New C2 Infrastructure and Obfuscation –
Privacy/Governance Feed

OysterLoader malware evolves into 2026, refining C2 infrastructure, obfuscation & infection stages – Read More  –  

Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware  – The Hacker News

Posted on February 16, 2026 By [email protected] (The Hacker News)
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware  – The Hacker News
Attack Feeds

This week’s recap shows how small gaps are turning into big entry points. Not always through new exploits, often through tools, add-ons, cloud setups, or workflows that people already trust and rarely question. Another signal: attackers are mixing old and new methods. Legacy botnet tactics, modern cloud abuse, AI assistance, and supply-chain exposure are being … Read More “Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware  – The Hacker News” »

Safe and Inclusive E‑Society: How Lithuania Is Bracing for AI‑Driven Cyber Fraud  – The Hacker News

Posted on February 16, 2026 By [email protected] (The Hacker News)
Safe and Inclusive E‑Society: How Lithuania Is Bracing for AI‑Driven Cyber Fraud  – The Hacker News
Attack Feeds

Presentation of the KTU Consortium Mission ‘A Safe and Inclusive Digital Society’ at the Innovation Agency event ‘Innovation Breakfast: How Mission-Oriented Science and Innovation Programmes Will Address Societal Challenges’. Technologies are evolving fast, reshaping economies, governance, and daily life. Yet, as innovation accelerates, so do digital risks. Technological change is no longer  – Read More  … Read More “Safe and Inclusive E‑Society: How Lithuania Is Bracing for AI‑Driven Cyber Fraud  – The Hacker News” »

Google Warns of In the Wild Exploit as It Patches New Chrome Zero Day –

Posted on February 16, 2026 By Joe-W
Google Warns of In the Wild Exploit as It Patches New Chrome Zero Day –
Privacy/Governance Feed

A high severity vulnerability in Google Chrome and allows remote attackers to execute code – Read More  –  

Google Ads and Claude AI Abused to Spread MacSync Malware via ClickFix  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on February 16, 2026 By Deeba Ahmed
Google Ads and Claude AI Abused to Spread MacSync Malware via ClickFix  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Cybersecurity experts at Moonlock Lab have discovered a new ClickFix attack. Hackers are using hijacked Google Ads and fake Claude AI guides to trick Mac users into installing the data-stealing MacSync malware.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft  – The Hacker News

Posted on February 16, 2026 By [email protected] (The Hacker News)
New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed details of a new mobile spyware platform dubbed ZeroDayRAT that’s being advertised on Telegram as a way to grab sensitive data and facilitate real-time surveillance on Android and iOS devices. “The developer runs dedicated channels for sales, customer support, and regular updates, giving buyers a single point of access to a … Read More “New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft  – The Hacker News” »

Crypto Payments to Human Traffickers Surges 85% –

Posted on February 16, 2026 By Joe-W
Crypto Payments to Human Traffickers Surges 85% –
Privacy/Governance Feed

Chainalysis warns that online fraud is fuelling sophisticated human trafficking operations – Read More  –  

Odido Breach Impacts Millions of Dutch Telco Users –

Posted on February 16, 2026 By Joe-W
Odido Breach Impacts Millions of Dutch Telco Users –
Privacy/Governance Feed

Dutch telco Odido has revealed a major data breach impacting over six million customers – Read More  –  

New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released  – The Hacker News

Posted on February 16, 2026 By [email protected] (The Hacker News)
New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released  – The Hacker News
Attack Feeds

Google on Friday released security updates for its Chrome browser to address a security flaw that it said has been exploited in the wild. The high-severity vulnerability, tracked as CVE-2026-2441 (CVSS score: 8.8), has been described as a use-after-free bug in CSS. Security researcher Shaheen Fazim has been credited with discovering and reporting the shortcoming … Read More “New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released  – The Hacker News” »

Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging  – The Hacker News

Posted on February 15, 2026 By [email protected] (The Hacker News)
Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging  – The Hacker News
Attack Feeds

Microsoft has disclosed details of a new version of the ClickFix social engineering tactic in which the attackers trick unsuspecting users into running commands that carry out a Domain Name System (DNS) lookup to retrieve the next-stage payload. Specifically, the attack relies on using the “nslookup” (short for nameserver lookup) command to execute a custom … Read More “Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging  – The Hacker News” »

287 Chrome Extensions Caught Harvesting Browsing Data from 37M Users  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on February 14, 2026 By Deeba Ahmed
287 Chrome Extensions Caught Harvesting Browsing Data from 37M Users  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

New investigation by Q Continuum reveals 287 Chrome extensions leaking the private browsing data of 37.4 million users to firms like Similarweb and Alibaba. Learn how these harmless tools turn your history into a product.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

What Interoperability in Healthcare Really Means for Security and Privacy  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on February 13, 2026 By Owais Sultan
What Interoperability in Healthcare Really Means for Security and Privacy  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Healthcare interoperability improves care but expands attack surfaces, increasing data exposure, compliance risk, and security challenges across connected systems.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations  – The Hacker News

Posted on February 13, 2026 By [email protected] (The Hacker News)
Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations  – The Hacker News
Attack Feeds

Several state-sponsored actors, hacktivist entities, and criminal groups from China, Iran, North Korea, and Russia have trained their sights on the defense industrial base (DIB) sector, according to findings from Google Threat Intelligence Group (GTIG). The tech giant’s threat intelligence division said the adversarial targeting of the sector is centered around four key themes: striking … Read More “Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations  – The Hacker News” »

Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs  – The Hacker News

Posted on February 13, 2026 By [email protected] (The Hacker News)
Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs  – The Hacker News
Attack Feeds

A previously undocumented threat actor has been attributed to attacks targeting Ukrainian organizations with malware known as CANFAIL. Google Threat Intelligence Group (GTIG) described the hack group as possibly affiliated with Russian intelligence services. The threat actor is assessed to have targeted defense, military, government, and energy organizations within the Ukrainian regional and  – Read … Read More “Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs  – The Hacker News” »

UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors  – The Hacker News

Posted on February 13, 2026 By [email protected] (The Hacker News)
UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors  – The Hacker News
Attack Feeds

A previously unknown threat actor tracked as UAT-9921 has been observed leveraging a new modular framework called VoidLink in its campaigns targeting the technology and financial services sectors, according to findings from Cisco Talos. “This threat actor seems to have been active since 2019, although they have not necessarily used VoidLink over the duration of … Read More “UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors  – The Hacker News” »

Munich Security Conference: Cyber Threats Lead G7 Risk Index, Disinformation Ranks Third –

Posted on February 13, 2026 By Joe-W
Munich Security Conference: Cyber Threats Lead G7 Risk Index, Disinformation Ranks Third –
Privacy/Governance Feed

G7 countries ranked cyber-attacks as the top risk, while BICS members placed cyber threats only as the eighth most pressing risk – Read More  –  

Static Design to Adaptive Control: How Artificial Intelligence Improves Modern Material Handling Equipment Systems  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on February 13, 2026 By Xiaoming Li
Static Design to Adaptive Control: How Artificial Intelligence Improves Modern Material Handling Equipment Systems  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

AI enables material handling systems to adapt to demand volatility through predictive design, dynamic control, and smarter maintenance without replacing core engineering.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

The $17 Billion Wake-Up Call: Securing Crypto in the Age of AI Scams  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on February 13, 2026 By Owais Sultan
The $17 Billion Wake-Up Call: Securing Crypto in the Age of AI Scams  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

AI-driven crypto scams surge as cybercrime hits $17B, with deepfakes, fraud kits, and industrial social engineering reshaping digital asset threats and defenses.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History  – The Hacker News

Posted on February 13, 2026 By [email protected] (The Hacker News)
Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History  – The Hacker News
Attack Feeds

Cybersecurity researchers have discovered a malicious Google Chrome extension that’s designed to steal data associated with Meta Business Suite and Facebook Business Manager. The extension, named CL Suite by @CLMasters (ID: jkphinfhmfkckkcnifhjiplhfoiefffl), is marketed as a way to scrape Meta Business Suite data, remove verification pop-ups, and generate two-factor authentication (2FA) codes.  – Read More  … Read More “Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History  – The Hacker News” »

Fake AI Assistants in Google Chrome Web Store Steal Passwords and Spy on Emails –

Posted on February 13, 2026 By Joe-W
Fake AI Assistants in Google Chrome Web Store Steal Passwords and Spy on Emails –
Privacy/Governance Feed

Hundreds of thousands of users have downloaded malicious AI extensions masquerading as ChatGPT, Gemini, Grok and others, warn cybersecurity researchers at LayerX – Read More  –  

npm’s Update to Harden Their Supply Chain, and Points to Consider  – The Hacker News

Posted on February 13, 2026 By [email protected] (The Hacker News)
npm’s Update to Harden Their Supply Chain, and Points to Consider  – The Hacker News
Attack Feeds

In December 2025, in response to the Sha1-Hulud incident, npm completed a major authentication overhaul intended to reduce supply-chain attacks. While the overhaul is a solid step forward, the changes don’t make npm projects immune from supply-chain attacks. npm is still susceptible to malware attacks – here’s what you need to know for a safer … Read More “npm’s Update to Harden Their Supply Chain, and Points to Consider  – The Hacker News” »

How to Rewrite Your Privacy Notice for DPDP Compliance – JISA Softech Pvt Ltd

Posted on February 13, 2026 By Aakash Chaudhary
How to Rewrite Your Privacy Notice for DPDP Compliance – JISA Softech Pvt Ltd
Privacy/Governance Feed

As the Digital Personal Data Protection Act moves into active enforcement, many organisations across India are reviewing one of… The post How to Rewrite Your Privacy Notice for DPDP Compliance appeared first on JISA Softech Pvt Ltd.  – Read More  – JISA Softech Pvt Ltd 

Urgent warnings from UK and US cyber agencies after Polish energy grid attack  – GRAHAM CLULEY

Posted on February 13, 2026 By Graham Cluley
Attack Feeds

A coordinated cyberattack that targeted Poland’s energy infrastructure in late December 2025 has prompted cybersecurity agencies to issue urgent warnings to critical national infrastructure operators on both sides of the Atlantic. Read more in my article on the Fortra blog.  – Read More  – GRAHAM CLULEY 

Researchers Observe In-the-Wild Exploitation of BeyondTrust CVSS 9.9 Vulnerability  – The Hacker News

Posted on February 13, 2026 By [email protected] (The Hacker News)
Researchers Observe In-the-Wild Exploitation of BeyondTrust CVSS 9.9 Vulnerability  – The Hacker News
Attack Feeds

Threat actors have started to exploit a recently disclosed critical security flaw impacting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) products, according to watchTowr. “Overnight we observed first in-the-wild exploitation of BeyondTrust across our global sensors,” Ryan Dewhurst, head of threat intelligence at watchTowr, said in a post on X. “Attackers are abusing  … Read More “Researchers Observe In-the-Wild Exploitation of BeyondTrust CVSS 9.9 Vulnerability  – The Hacker News” »

Apple discloses first actively exploited zero-day of 2026  – CyberScoop

Posted on February 12, 2026 By Matt Kapko
Apple discloses first actively exploited zero-day of 2026  – CyberScoop
Attack Feeds

Apple disclosed a zero-day vulnerability Wednesday that the vendor warned was previously “exploited in an extremely sophisticated attack against specific targeted individuals,” the company said in a security update. The memory-corruption vulnerability — CVE-2026-20700 — affects iPhones and iPads and was exploited on devices running versions of iOS before iOS 26. The Cybersecurity and Infrastructure … Read More “Apple discloses first actively exploited zero-day of 2026  – CyberScoop” »

Proofpoint acquires Acuvity to tackle the security risks of agentic AI  – CyberScoop

Posted on February 12, 2026 By Greg Otto
Proofpoint acquires Acuvity to tackle the security risks of agentic AI  – CyberScoop
Attack Feeds

Proofpoint announced Thursday it has acquired Acuvity, an AI security startup, as the cybersecurity company moves to address security risks stemming from widespread corporate adoption of agentic AI. The acquisition strengthens Proofpoint‘s capabilities in monitoring and securing AI-powered systems that are increasingly handling sensitive business functions across enterprises.  Financial terms of the deal were not … Read More “Proofpoint acquires Acuvity to tackle the security risks of agentic AI  – CyberScoop” »

Google finds state-sponsored hackers use AI at ‘all stages’ of attack cycle   – CyberScoop

Posted on February 12, 2026 By djohnson
Google finds state-sponsored hackers use AI at ‘all stages’ of attack cycle   – CyberScoop
Attack Feeds

A new report from Google found evidence that state-sponsored hacking groups have leveraged AI tool Gemini at nearly every stage of the cyber attack cycle. The research underscores how AI tools have matured in their cyber offensive capabilities, even as it doesn’t reveal novel or paradigm shifting uses of the technology. John Hultquist, chief analyst … Read More “Google finds state-sponsored hackers use AI at ‘all stages’ of attack cycle   – CyberScoop” »

Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems  – The Hacker News

Posted on February 12, 2026 By [email protected] (The Hacker News)
Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems  – The Hacker News
Attack Feeds

Cybersecurity researchers have discovered a fresh set of malicious packages across npm and the Python Package Index (PyPI) repository linked to a fake recruitment-themed campaign orchestrated by the North Korea-linked Lazarus Group. The coordinated campaign has been codenamed graphalgo in reference to the first package published in the npm registry. It’s assessed to be active … Read More “Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems  – The Hacker News” »

CISA to host industry feedback sessions on cyber incident reporting regulation  – CyberScoop

Posted on February 12, 2026 By Tim Starks
CISA to host industry feedback sessions on cyber incident reporting regulation  – CyberScoop
Attack Feeds

The Cybersecurity and Infrastructure Security Agency will hold sector-by-sector town halls in the coming weeks to get feedback on a stalled regulation requiring critical infrastructure owners and operators to report when they suffer major cyberattacks. The meeting dates, set to be published in the Federal Register Friday, would “allow external stakeholders a limited additional opportunity … Read More “CISA to host industry feedback sessions on cyber incident reporting regulation  – CyberScoop” »

Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support  – The Hacker News

Posted on February 12, 2026 By [email protected] (The Hacker News)
Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support  – The Hacker News
Attack Feeds

Google on Thursday said it observed the North Korea-linked threat actor known as UNC2970 using its generative artificial intelligence (AI) model Gemini to conduct reconnaissance on its targets, as various hacking groups continue to weaponize the tool for accelerating various phases of the cyber attack life cycle, enabling information operations, and even conducting model extraction … Read More “Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support  – The Hacker News” »

Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems  – The Hacker News

Posted on February 12, 2026 By [email protected] (The Hacker News)
Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems  – The Hacker News
Attack Feeds

Cybersecurity researchers have discovered a fresh set of malicious packages across npm and the Python Package Index (PyPI) repository linked to a fake recruitment-themed campaign orchestrated by the North Korea-linked Lazarus Group. The coordinated campaign has been codenamed graphalgo in reference to the first package published in the npm registry. It’s assessed to be active … Read More “Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems  – The Hacker News” »

World Leaks Ransomware Group Adds Stealthy, Custom Malware ‘RustyRocket’ to Attacks –

Posted on February 12, 2026 By Joe-W
World Leaks Ransomware Group Adds Stealthy, Custom Malware ‘RustyRocket’ to Attacks –
Privacy/Governance Feed

Accenture Cybersecurity warns over difficult to detect, “sophisticated toolset” being deployed as part of extortion campaigns – Read More  –  

Nation-State Hackers Embrace Gemini AI for Malicious Campaigns, Google Finds –

Posted on February 12, 2026 By Joe-W
Nation-State Hackers Embrace Gemini AI for Malicious Campaigns, Google Finds –
Privacy/Governance Feed

Google researchers found that government-backed hackers now use AI throughout the whole attack lifecycle – Read More  –  

ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories  – The Hacker News

Posted on February 12, 2026 By [email protected] (The Hacker News)
ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories  – The Hacker News
Attack Feeds

Threat activity this week shows one consistent signal — attackers are leaning harder on what already works. Instead of flashy new exploits, many operations are built around quiet misuse of trusted tools, familiar workflows, and overlooked exposures that sit in plain sight. Another shift is how access is gained versus how it’s used. Initial entry … Read More “ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories  – The Hacker News” »

The CTEM Divide: Why 84% of Security Programs Are Falling Behind  – The Hacker News

Posted on February 12, 2026 By [email protected] (The Hacker News)
The CTEM Divide: Why 84% of Security Programs Are Falling Behind  – The Hacker News
Attack Feeds

A new 2026 market intelligence study of 128 enterprise security decision-makers (available here) reveals a stark divide forming between organizations – one that has nothing to do with budget size or industry and everything to do with a single framework decision. Organizations implementing Continuous Threat Exposure Management (CTEM) demonstrate 50% better attack surface visibility, 23-point  … Read More “The CTEM Divide: Why 84% of Security Programs Are Falling Behind  – The Hacker News” »

AI Skills Represent Dangerous New Attack Surface, Says TrendAI –

Posted on February 12, 2026 By Joe-W
AI Skills Represent Dangerous New Attack Surface, Says TrendAI –
Privacy/Governance Feed

New TrendAI report warns that most security tools can’t protect against attacks on AI skills artifacts – Read More  –  

Time to Exploit Plummets as N-Day Flaws Dominate –

Posted on February 12, 2026 By Joe-W
Time to Exploit Plummets as N-Day Flaws Dominate –
Privacy/Governance Feed

Flashpoint warns of a dramatic drop in the average time between vulnerability disclosure and exploitation – Read More  –  

Can you help the NCSC with the next phase of EASM research?  – NCSC Feed

Posted on February 12, 2026 By Joe-W
Can you help the NCSC with the next phase of EASM research?  – NCSC Feed
Gov/ISAC Feeds

Organisations with experience in external attack surface management can help us shape future ACD 2.0 services. – Read More – NCSC Feed 

83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure  – The Hacker News

Posted on February 12, 2026 By [email protected] (The Hacker News)
83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure  – The Hacker News
Attack Feeds

A significant chunk of the exploitation attempts targeting a newly disclosed security flaw in Ivanti Endpoint Manager Mobile (EPMM) can be traced back to a single IP address on bulletproof hosting infrastructure offered by PROSPERO. Threat intelligence firm GreyNoise said it recorded 417 exploitation sessions from 8 unique source IP addresses between February 1 and … Read More “83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure  – The Hacker News” »

Polish hacker charged seven years after massive Morele.net data breach  – GRAHAM CLULEY

Posted on February 12, 2026 By Graham Cluley
Polish hacker charged seven years after massive Morele.net data breach  – GRAHAM CLULEY
Attack Feeds

A 29-year-old Polish man has been charged in connection with a data breach that exposed the personal details of around 2.5 million customers of the popular Polish e-commerce website Morele.net. Read more in my article on the Hot for Security blog.  – Read More  – GRAHAM CLULEY 

Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Apple Devices  – The Hacker News

Posted on February 12, 2026 By [email protected] (The Hacker News)
Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Apple Devices  – The Hacker News
Attack Feeds

Apple on Wednesday released iOS, iPadOS, macOS Tahoe, tvOS, watchOS, and visionOS updates to address a zero-day flaw that it said has been exploited in sophisticated cyber attacks. The vulnerability, tracked as CVE-2026-20700 (CVSS score: N/A), has been described as a memory corruption issue in dyld, Apple’s Dynamic Link Editor. Successful exploitation of the vulnerability … Read More “Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Apple Devices  – The Hacker News” »

Posts pagination

Previous 1 … 37 38 39 40 Next
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.